summaryrefslogtreecommitdiffstats
path: root/etc/shorewall/rules
diff options
context:
space:
mode:
Diffstat (limited to 'etc/shorewall/rules')
-rw-r--r--etc/shorewall/rules32
1 files changed, 32 insertions, 0 deletions
diff --git a/etc/shorewall/rules b/etc/shorewall/rules
new file mode 100644
index 00000000..db08726c
--- /dev/null
+++ b/etc/shorewall/rules
@@ -0,0 +1,32 @@
+#
+# Shorewall version 4.0 - Sample Rules File for one-interface configuration.
+# Copyright (C) 2006 by the Shorewall Team
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# See the file README.txt for further details.
+#------------------------------------------------------------------------------------------------------------
+# For information on entries in this file, type "man shorewall-rules"
+######################################################################################################################################################################################
+#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH
+# PORT PORT(S) DEST LIMIT GROUP
+#SECTION ALL
+#SECTION ESTABLISHED
+#SECTION RELATED
+SECTION NEW
+
+# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
+
+Ping(DROP) net $FW
+
+# Permit all ICMP traffic FROM the firewall TO the net zone
+
+ACCEPT $FW net icmp
+
+# http and ssh are allowed
+ACCEPT net $FW tcp 80
+ACCEPT net $FW tcp 22
+